XSS in bugtask delete confirmation dialog (and possibly others)
Bug #1057901 reported by
Ian Booth
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Launchpad itself |
Fix Released
|
Critical
|
Ian Booth |
Bug Description
The dialog confirmation text when deleting a bugtask has the bug title inserted directly into the HTML.
Related branches
lp:~wallyworld/launchpad/confirmation-dialog-xss-1057901
- William Grant: Approve (code)
-
Diff: 67 lines (+12/-13)2 files modifiedlib/lp/app/javascript/information_type.js (+6/-6)
lib/lp/bugs/javascript/bugtask_index.js (+6/-7)
tags: |
added: javascript qa-ok xss removed: qa-needstesting |
Changed in launchpad: | |
status: | Fix Committed → Fix Released |
visibility: | private → public |
To post a comment you must log in.
Fixed in stable r16048 <http:// bazaar. launchpad. net/~launchpad- pqm/launchpad/ stable/ revision/ 16048>.